CVE-2024-9779 - CVE House
Back to Database
Status published High CVE-2024-9779

Open-cluster-management-io/ocm: cluster-manager permissions may allow a worker node to obtain service account tokens

Vulnerability Description

A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name "cluster-manager" which is bound to a ClusterRole also named "cluster-manager", which includes the permission to create Pod resources. If this deployment runs a pod on an attacker-controlled node, the attacker can obtain the cluster-manager's token and steal any service account token by creating and mounting the target service account to control the whole cluster.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9779

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Red Hat would like to thank Nanzi Yang and Xingyu Liu for reporting this issue.

Affected Vendor

Affected Software

Red Hat Advanced Cluster Management for Kubernetes 2
Vulnerable Versions:
0.12.0, 0.13.0

Timeline

Official Publish: December 17th, 2024
Last Modified: February 25th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N

Weaknesses (CWE)